Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
111 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.91% | — | Xtendify Woffice | 2/8/2025 | 17/6/2026 | The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the woffice_file_manager_delete() function in all versions up to, and including, 5.4.26. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete… | |
| Aplazada | Media (6.1) | 0.24% | — | Fedify HolloAI | 17/7/2025 | 17/6/2026 | Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to 0.6.5 allow HTML form elements to be submitted, making the software vulnerable to HTML injection. Version 0.6.5 fixes the issue. | |
| Analizada | Alta (7.2) | 0.78% | — | Langgenius Dify | 7/7/2025 | 17/6/2026 | langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root permissions. The vulnerability arises from the ability to override global functions in JavaScript, such as parseInt, before sandbox security restrictions are imposed. This… | |
| Analizada | Media (5.4) | 0.37% | — | Langgenius Dify | 7/7/2025 | 30/9/2026 | An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacker to obtain the administrator's token by sending a payload in the published chat. When the administrator views the conversation content through the monitoring/log… | |
| Analizada | Media (5.3) | 0.28% | — | Langgenius Dify | 17/6/2025 | 17/6/2026 | Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by web applications. Attackers can use website vulnerabilities to inject malicious script code into web pages. This may result in a cross-site scripting (XSS) attack when a user browses these web pages.… | |
| Analizada | Baja (2.3) | 0.24% | — | Langgenius Dify | 28/4/2025 | 17/6/2026 | DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or consent. This can lead to unauthorized actions… | |
| Analizada | Alta (7.6) | 0.34% | — | Langgenius Dify | 25/4/2025 | 17/6/2026 | Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though the web UI of APP orchestration is not presented for a normal user. This access control flaw allows non-admin users to make unauthorized access and changes on the… | |
| Analizada | Media (6.5) | 0.42% | — | Langgenius Dify | 18/4/2025 | 17/6/2026 | Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or disable apps through the API, even though the web UI button for this action is disabled and normal users are not permitted to make such changes. This access control… | |
| Analizada | Media (6.5) | 0.30% | — | Langgenius Dify | 18/4/2025 | 17/6/2026 | Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted permissions to edit APP names, descriptions and icons. This access control flaw allows non-admin users to modify app details, despite being restricted from… | |
| Analizada | Media (4.3) | 0.29% | — | Langgenius Dify | 18/4/2025 | 17/6/2026 | Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are improperly granted permissions to export APP DSL. The feature in '/export' should only allow administrator users to export DSL. A workaround for this vulnerability… | |
| Aplazada | Alta (7.1) | 0.29% | — | Push-notification-by-feedifyAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in feedify Feedify – Web Push Notifications push-notification-by-feedify allows Reflected XSS.This issue affects Feedify – Web Push Notifications: from n/a through <= 2.4.5. | |
| Analizada | Media (4.8) | 0.17% | — | Langgenius Dify | 14/4/2025 | 17/6/2026 | Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. | |
| Analizada | Alta (7.1) | 0.27% | — | Feedify WEB Push Notifications | 10/4/2025 | 17/6/2026 | The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Crítica (9.8) | 0.66% | — | Xtendify Woffice | 4/4/2025 | 17/6/2026 | The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to register with an Administrator role if a custom login form is being… | |
| Analizada | Media (5.4) | 0.14% | — | Xtendify Woffice | 4/4/2025 | 17/6/2026 | The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.4.21. This is due to missing or incorrect nonce validation on the 'woffice_handle_user_approval_actions' function. This makes it possible for unauthenticated attackers to approve registration for… | |
| Analizada | Alta (8.8) | 0.85% | — | Xtendify Woffice | 4/4/2025 | 17/6/2026 | The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'saveFeaturedImage' function in all versions up to, and including, 5.4.21. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (5.9) | 0.37% | — | Astoundify WP Modal Popup With Cookie IntegrationAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Modal Popup with Cookie Integration wp-modal-popup-with-cookie-integration allows Stored XSS.This issue affects WP Modal Popup with Cookie Integration: from n/a through <= 2.4. | |
| Aplazada | Media (5.9) | 0.21% | — | Astoundify JOB Colors FOR WP JOB ManagerAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify Job Colors for WP Job Manager wp-job-manager-colors allows Stored XSS.This issue affects Job Colors for WP Job Manager: from n/a through <= 1.0.4. | |
| Analizada | Alta (8.8) | 0.59% | — | Langgenius Dify | 20/3/2025 | 17/6/2026 | A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts, by exploiting a weak pseudo-random number generator (PRNG) used for generating password reset codes. The application uses `random.randint` for this purpose, which is not suitable for cryptographic… | |
| Analizada | Alta (8.8) | 1.1% | — | Dify | 20/3/2025 | 17/6/2026 | A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the function `vn.get_training_plan_generic(df_information_schema)`, which does not properly sanitize user inputs before executing queries using the… | |
| Analizada | Media (6.5) | 0.50% | — | Langgenius Dify | 20/3/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledge' section when uploading DOCX files. If an external relationship exists in the DOCX file, the reltype value is requested as a URL using the 'requests' module instead of… | |
| Analizada | Alta (8.1) | 0.65% | — | Langgenius Dify | 20/3/2025 | 17/6/2026 | In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the password of any user, including administrators. This vulnerability can lead to a complete compromise of the application. | |
| Analizada | Media (6.5) | 0.65% | — | Langgenius Dify | 20/3/2025 | 17/6/2026 | langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API `POST /console/api/workspaces/current/tool-provider/api/test/pre`. Attackers can set the `url` in the `servers` dictionary in OpenAI's schema with… | |
| Analizada | Alta (8.1) | 0.67% | — | Langgenius Dify | 20/3/2025 | 17/6/2026 | langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess attempts for password reset. This allows an unauthenticated attacker to reset owner, admin, or other user passwords within a few hours by guessing the six-digit code, resulting in a complete… | |
| Analizada | Media (5.4) | 0.43% | — | Langgenius Dify | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation and sanitization of user input in SVG markdown support within the chatbot feature. An attacker can exploit this vulnerability by injecting malicious SVG content, which can… |